
This yet again underlines why servers should NOT have direct internet access.
They should only have whitelisted connections to distribution repositories and update servers to stay current with security patches. Letting servers freely chat with the internet is asking for trouble.
In this case, proper egress filtering would have prevented both the C2 connections and the Dropbox exfiltration.